Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '30525' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '15602' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '31137' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '31320' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '21129' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '8035' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '17733' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '8034' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '20881' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '4360' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '13749' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '8962' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '20297' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '30427' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10751' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '26504' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '22025' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '16805' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10877' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '654' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '15230' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '30023' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '15879' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '29871' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '30364' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10229' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '2815' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '19307' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '24403' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '5316' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '11000' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '26535' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '26719' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10505' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '3434' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '13131' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '30178' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '16280' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1025' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '32186' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '11648' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6025' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '21872' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6397' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '27306' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '18536' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '5225' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10782' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '16991' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10010' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '2261' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '17083' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '13191' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '16465' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '31382' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '12482' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1239' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '18166' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '29530' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '24433' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6953' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '26628' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '9579' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '26626' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6706' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '16066' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '9053' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6306' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '19741' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '25298' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '14922' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '12329' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '13871' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '2629' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '29469' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '19247' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1054' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '12174' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '18196' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '13099' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1702' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '28140' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '17331' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '3433' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '20604' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '17144' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '16961' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '1426' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '22242' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '158' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '32711' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '29437' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10815' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '3803' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '9639' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '20357' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '27029' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '3650' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '25609' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '10197' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '20328' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '28602' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '6584' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '20853' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '32681' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '2908' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '11153' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '22273' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '11802' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '31816' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '26287' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '12885' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '29346' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '8066' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '13346' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '23816' = '<Full path to file>'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] '2722' = '<Full path to file>'
- [HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- C:\lsass.exe
- '12#.#58.69.126':3128
- '69.##8.255.138':3128
- '24.#6.45.53':3128
- '18#.#4.62.125':3128
- '77.##.35.149':3128
- '83.##.223.22':3128
- '13#.#43.186.16':3128
- '66.##.101.49':3128
- '84.##4.13.192':3128
- '19#.#20.109.140':3128
- '98.##2.24.182':3128
- '18#.#.159.231':3128
- '86.#1.107.6':3128
- '17#.#3.144.69':3128
- '65.##5.224.129':3128
- '89.##9.241.114':3128
- '61.##.186.142':3128
- '18#.#21.96.94':3128
- '68.##1.83.197':3128
- '20#.#6.200.105':3128
- '85.##.72.196':3128
- '64.##3.240.133':3128
- '76.##.94.234':3128
- '89.##3.142.181':3128
- '76.##.135.63':3128
- '84.##5.174.41':3128
- '68.##4.145.55':3128
- '12#.#38.106.113':3128
- '70.##.106.187':3128
- '17#.#70.168.179':3128
- '86.##6.14.42':3128
- '67.##1.33.242':3128
- '99.##5.118.250':3128
- '83.##3.75.16':3128
- '20#.#10.108.46':3128
- '11#.#97.9.168':3128
- '24.##.219.207':3128
- '83.#.194.14':3128
- '12#.#25.24.25':3128
- '84.##.83.186':3128
- '98.##5.12.201':3128
- '69.##4.125.151':3128
- '69.##5.116.91':3128
- '99.##1.99.45':3128
- '98.##2.108.247':3128
- '12#.#44.227.211':3128
- '99.##0.169.20':3128
- '82.##6.254.67':3128
- '18#.1.3.65':3128
- '19#.#1.248.253':3128
- '70.##6.55.65':3128
- '85.##7.235.212':3128
- '91.##.85.215':3128
- '78.##2.50.252':3128
- '70.##.202.16':3128
- '24.##2.213.139':3128
- '19#.#5.174.228':3128
- '96.#.160.38':3128
- '87.##.143.116':3128
- '20#.#31.239.149':3128
- '17#.#1.24.213':3128
- '66.##1.37.201':3128
- '20#.#30.105.180':3128
- '11#.#4.73.86':3128
- '89.##.138.57':3128
- '19#.#00.12.15':3128
- '71.##0.146.108':3128
- '20#.#35.82.105':3128
- '72.##3.138.154':3128
- '24.##.179.129':3128
- '12#.#41.131.226':3128
- '21#.#12.15.216':3128
- '91.##6.14.74':3128
- '71.##9.166.160':3128
- '24.##.220.189':3128
- '12#.#8.184.181':3128
- '89.##.129.35':3128
- '21#.#0.69.240':3128
- '96.#.109.140':3128
- '86.##3.156.48':3128
- '11#.#4.134.215':3128
- '85.#4.132.8':3128
- '18#.#2.128.8':3128
- '72.##9.147.86':3128
- '94.##5.172.144':3128
- '70.#2.7.63':3128
- '71.##8.78.81':3128
- '94.##5.247.126':3128
- '20#.#9.173.56':3128
- '20#.#68.252.115':3128
- '17#.#5.190.225':3128
- '12#.#04.12.21':3128
- '89.##2.29.54':3128
- '74.##.93.206':3128
- '24.##3.45.96':3128
- '24.##6.212.57':3128
- '17#.#9.33.209':3128
- '18#.#1.253.182':3128
- '24.##8.74.89':3128
- '99.##4.82.22':3128
- '86.##1.90.55':3128
- '24.##.201.111':3128
- '12#.#53.229.62':3128
- '83.##6.140.41':3128
- '18#.#06.57.161':3128
- '84.##.80.160':3128
- '99.##6.21.23':3128
- '20#.#18.148.104':3128
- '24.##.210.128':3128
- '18#.#5.41.129':3128
- '12#.#4.149.90':3128
- '59.#6.43.53':3128
- '70.##6.153.37':3128
- '69.##5.119.42':3128
- '71.##5.9.218':3128
- '78.##.214.156':3128
- '66.##3.117.18':3128
- '83.##.207.154':3128
- '86.##1.115.84':3128
- '93.##.198.215':3128
- '84.##4.197.145':3128
- '20#.#22.239.156':3128
- '21#.#2.75.232':3128
- '96.##.65.255':3128
- '12#.#06.202.130':3128
- '85.##5.181.33':3128
- '21#.#64.96.55':3128
- '24.#6.61.39':3128
- '11#.#37.24.57':3128
- '84.#.160.87':3128
- '74.##.175.57':3128
- '82.##1.119.31':3128
- '66.##.85.235':3128
- '20#.#5.57.254':3128
- '88.##5.124.142':3128
- '20#.#71.244.183':3128
- '99.##0.158.15':3128
- '96.#0.52.44':3128
- '18#.#58.232.173':3128
- '78.##.20.218':3128
- '89.##3.32.197':3128
- '69.##3.88.223':3128
- '68.##.136.70':3128
- '18#.#5.43.167':3128
- '18#.#0.127.194':3128
- '75.#5.92.92':3128
- '68.##.50.185':3128
- '17#.#0.70.26':3128
- '41.##5.115.95':3128
- '77.##2.161.101':3128
- '95.##4.95.34':3128
- '99.##5.68.251':3128
- '82.##2.182.2':3128
- '11#.#0.210.190':3128
- '69.##7.124.222':3128
- '88.##5.245.61':3128
- '86.##5.93.118':3128
- '89.#1.45.75':3128
- 'C:\lsass.exe' exe <Full path to file>
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Full path to file>"